The Register Home Page

back to article Criminal wannabes even more dangerous than the pros, says ex-FBI cyber chief

It's the biggest threat today, but it took her a while to appreciate it. After spending two decades at the FBI and much of that time working to intercept and stop cyber threats from the likes of China and Russia, Halcyon Ransomware Research Center SVP Cynthia Kaiser says she was a "latercomer to really wanting to focus on …

  1. elsergiovolador Silver badge

    Functionally Broken Institution

    Guys who missed that their entire administration is now compromised by Russia lecture about security.

    They are a laughing stock of intelligence community.

  2. Bebu sa Ware Silver badge
    Big Brother

    "you might never get your data back"

    "can have disastrous, destructive impacts on business operations."

    And that is necessarily a bad thing ?

    By now if you haven't learnt, you never will. Arguably it would be a desirable outcome for all concerned if both you and your business were to disappear down the gurgler. Doubly so if you have been guzzling the AI lemonade and retrenched all your relevant staff.

  3. Bebu sa Ware Silver badge
    Holmes

    Sicarii encryptor generates a new cryptographic key pair

    "The Sicarii encryptor generates a new cryptographic key pair during every execution - but then discards the private key, "

    That implies that asymmetric (public key) encryption is employed. Discarding the private key is legitimate as long as you retain the public key for decryption.

    From a quick search it seems Sicarii used AES which is symmetric crypto (encryption and decryption use the same key) so deleting that key even accidentally by overwriting with new key material before recording the first key is a big oops.

    I assume the idea is to generate a new AES key for each file and record the key and keyid in some sort of database and prepend a header containing the keyid and any salt (IV) to encrypted file. When done the key database is also encryped ... with some publlc key crypto and the private key is deleted with the public key retained by the villains to be later supplied to the victim for a fee (POA.)

    Not exactly rocket surgery but this Russian group masquerading as Israelis (the unspeakable as the untouchable?) managed to cock it up in the simplest way possible.

    1. doublelayer Silver badge

      Re: Sicarii encryptor generates a new cryptographic key pair

      "Discarding the private key is legitimate as long as you retain the public key for decryption."

      That's not how public/private key encryption works. You can encrypt with the public something which you need the private to decrypt, but not the other way. What they were likely doing is encrypting each file symmetrically, encrypting that symmetric key with the public key, and then you could use the private key to recover the keys to decrypt. Except they deleted the private key so they can't do that. Generating a fresh keypair on the victim's computer is also stupid when you could just include the public key they're supposed to use.

  4. VicMortimer Silver badge
    FAIL

    Want to stop ransomware? Ban paying ransom.

    The ONLY way ransomware is ever going to stop is if paying becomes a crime - with actual prison time for CEOs who pay.

    Ransomware exists because getting money is possible. Stop the money, stop the ransomware.

    1. druck Silver badge

      Re: Want to stop ransomware? Ban paying ransom.

      Almost. Ransomware exists because getting cryptocurrency is legal. Stop the crypto, stop the ransomware.

      No other form of money can flow so easily and anonymously across international boarders without restriction, such scams didn't exist before it, and wont exist after it.

      1. doublelayer Silver badge

        Re: Want to stop ransomware? Ban paying ransom.

        "such scams didn't exist before it"

        Complete rubbish. Money managed to cross borders, even illegally, before cryptocurrency. As long as paying it is still legal, criminals can come up with a different way to pay and companies can go along with that. Banning payments will be more successful and more obtainable than banning cryptocurrency.

        1. druck Silver badge

          Re: Want to stop ransomware? Ban paying ransom.

          We aren't taking about any type of scams. Name any ransomware crew that demanded payment in something other than cryptocurrency.

      2. Alan Brown Silver badge

        Re: Want to stop ransomware? Ban paying ransom.

        If it wasn't crypto it'd be something else. That's just a tool.

        Italy's kidnapping problem was almost wiped out by criminalising ransom payments (gangs were taking ransoms and killing the victim anyway, similar to what we're seeing with software ransoms)

  5. Claptrap314 Silver badge

    No news day El Reg?

    I'm trying to figure out what useful information is surfaced in this article. You've got some mid-level FBI agent who was so ensconced in her little bubble that when she stepped outside, she was shocked that the sun was so bright. Reminds me of that joker Biden appointed who didn't realize cybersecurity was a major threat until 2019.

    If someone is so stupid as to fail to understand someone so obvious and so unaware as to announce the fact, quietly just bury the interview. No need to further shame them by publicizing the interview.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon